CVE-2025-64899

7.8

Adobe · Acrobat Reader

Adobe Acrobat Reader is affected by an out-of-bounds read vulnerability that may allow an attacker to execute arbitrary code via a crafted malicious file.

Executive summary

A critical out-of-bounds read vulnerability in Adobe Acrobat Reader allows for potential remote code execution through user interaction with a malicious file.

Vulnerability

This vulnerability is an out-of-bounds read flaw (CWE-125) triggered when the software parses a crafted file. While the attack vector is local, it requires user interaction, and successful exploitation permits code execution in the context of the current user.

Business impact

The potential for arbitrary code execution poses a significant threat to organizational security, as it allows attackers to compromise user workstations and potentially pivot into internal networks. With a CVSS score of 7.8, this high-severity vulnerability represents a substantial risk to data confidentiality, integrity, and system availability. Successful exploitation could lead to unauthorized access to sensitive documents and administrative credentials stored on the affected host.

Remediation

Immediate Action: Review the official Adobe security advisory (APSB25-119) and apply the latest security patches provided by the vendor to all affected installations.

Proactive Monitoring: Monitor endpoint activity for suspicious file parsing operations or unexpected child processes spawned by the Acrobat Reader application.

Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block malicious file execution attempts, and encourage users to exercise caution when opening untrusted PDF files.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

Given the potential for remote code execution, organizations should prioritize patching Adobe Acrobat Reader across all endpoints. Administrators should verify that automatic updates are enabled or push the relevant patches through centralized management tools to minimize the window of exposure.

More Adobe CVEs

Sources